Proactive Threat Defence: Know(ing) Your D.N.A

After one of my recent posts on LinkedIn, which mentioned the importance of understanding three critical areas of proactive threat defence: your data, your network, and your adversary, I received a few DMs requesting more information and asking if I could elaborate with some practical guidance on how to apply this thinking in the real world.

In this blog post, I’ll do just that. 

Before diving in, I’ll cover the two approaches to threat defence: proactive and reactive. This will give you a clear understanding of the main differences between the two and highlight the key characteristics of each.

Proactive vs. Reactive

Threat Defence: Proactive vs. Reactive

Proactive threat defence is a forward-looking cybersecurity strategy focused on anticipating and preventing attacks before they can cause actual harm. It involves continuously observing, identifying, and protecting against potential risks, ensuring that threats are mitigated and stopped before they can reach critical systems.

By increasing the time to impact—delaying or preventing the effect of an attack—organisations can create a security buffer by applying layered defence mechanisms (defence in depth principle) that significantly lower the chances of a breach or compromise.

In contrast, reactive threat defence kicks in after an attack, focusing on quick detection, organised response, and efficient recovery to minimise damage. While reactive measures are essential for mitigating the effects of an attack, a proactive approach strengthens an organisation’s overall security posture, reducing both the likelihood and severity of incidents.

By balancing proactive and reactive strategies, businesses can better safeguard their assets and maintain operational resilience in a continuously evolving threat landscape.

Know Your Data

Understanding your data is the foundation of an effective proactive threat defence strategy. This involves identifying, classifying, and protecting your organisation's critical information assets.

Data discovery and classification

Start by conducting a comprehensive data inventory across your entire organisation. Identify where sensitive data is stored, including databases, file servers, cloud storage (S3 buckets, Azure blob storage, etc.), and end-user devices. Once you've mapped out your data landscape, classify information based on its sensitivity and importance to your business operations.

There are three main approaches to data classification - content-based, context-based, and user-based.

Content-based classification

This approach analyses the actual content of files and documents to determine their sensitivity level.

Example: Microsoft Purview Information Protection (formerly MIP) uses machine learning algorithms to automatically classify and label documents based on their content, helping organisations protect sensitive information across their Microsoft 365 ecosystem.

There are some good third-party alternatives to Microsoft Purview, like Trellix DLP and ManageEngine.

Context-based classification

Context-based classification considers factors such as file location, creator, and application to determine sensitivity.

Example: Spirion's data classification software uses both content and context-based classification methods to provide a comprehensive approach to data categorisation.

User-based classification

Classifying data based on end-user knowledge and discretion.

This form of data classification requires input from business application owners and product development teams to understand what specific information assets are being used/consumed by the respective systems and applications.

Customisable classification schemes

Modern tools often allow organisations to define custom classification schemes tailored to their specific needs and compliance requirements.

Example: SISA Radar enables organisations to create customised algorithms for data analysis, allowing for more accurate and relevant classification based on the organisation's unique data landscape.

By leveraging these modern approaches and tools, organisations can gain an accurate and thorough understanding of their sensitive data landscape, enabling more effective data protection, compliance management, and risk mitigation strategies. It's important to note that the choice of tool or approach should be based on the organisation's specific needs/requirements, infrastructure stack, and compliance requirements.

Not all data is created equal.

 

Know Your Network

Next, it’s time to dive into the network. A deep understanding of your network infrastructure is essential for proactive threat defence. This knowledge enables you to identify vulnerabilities, detect anomalies, and respond quickly to potential network-based threats.

Your network presents one of the most common attack vectors for malicious threats, but it is essential to any technology and business solution we use today.

Network mapping and asset management

Create a detailed map of your network infrastructure, including all devices and appliances, application environments, and ingress/egress connections. Maintain an up-to-date inventory of hardware and software assets, including their configurations, firmware versions and patch levels. This detailed view helps you identify potential weak points and prioritise security efforts.

Consider using open-source tools like Nagios and Cacti to get started and gain deeper network visibility across your organisation.

Protip: accurate and up-to-date network architecture documentation is incredibly valuable. This will save time and remove many assumptions when preparing for the next migration project or change initiative.

Network segmentation

Implement network segmentation to limit the potential spread of threats within your organisation. Plan and design your network into separate zones based on business criticality, security requirements and data sensitivity. This approach can contain breaches and minimise the impact of successful attacks.

Continuous monitoring

Deploy network monitoring tools that use machine learning and behavioural analytics to detect anomalies and potential threats in real-time. Implement a Security Information and Event Management (SIEM) system to correlate and analyse log data from various sources across your network.

 

Know Your Adversary

The third and final piece of the proactive threat defence tri-force (for the Zelda fans) is about understanding potential adversaries' tactics, techniques, and procedures (TTPs). Gathering detailed knowledge of adversary behaviour is crucial for proactive threat defence.

This knowledge allows you to anticipate and prepare for specific types of attacks, from common phishing or social engineering to business email compromise (BEC), ransomware, supply chain attacks and everything in between.

Threat Intelligence

Subscribe to threat intelligence feeds and platforms like Open Threat Exchange or SANS Internet Storm Centre to stay informed about emerging threats and attack patterns relevant to your industry. Analyse this information to identify potential vulnerabilities in your applications, networks, and systems and develop informed defence strategies.

It’s also important to know the different types of threat intelligence; again, not all data is created equal, and various kinds of threat intelligence serve different purposes. There are four types of Cyber Threat Intelligence (CTI), they are:

  1. Technical Threat Intelligence

  2. Strategic Threat Intelligence

  3. Tactical Threat Intelligence (I wrote a whole article just on this, here)

  4. Operational Threat Intelligence

For more information on these different categories, check out this article here.

Adversary Emulation

Conduct regular adversary emulation exercises to test your defences against real-world attack scenarios. Use frameworks like MITRE ATT&CK to simulate various threat actor behaviours and identify gaps in your security posture.

A few months ago, I presented a talk on ‘proactive threat defence using an adversarial mindset’. I demonstrated a practical way to identify attack behaviour patterns (TTPs) across multiple threat actors operating in similar regions and industry sectors using MITRE’s ATT&CK Navigator tool in this presentation.

I highly recommend getting to know the basics of ATT&CK Navigator and experimenting with adding multiple layers together to reveal common attack techniques. Doing this will give you a good idea of where to focus your detection and prevention efforts.

Red Canary’s Atomic Red Team is another great resource for running a series of simulated adversary attacks that are mapped to the MITRE ATT&CK framework. This type of simulated testing is an excellent way to test and validate the effectiveness of your defences.

Threat Hunting

Implement a proactive threat-hunting program to actively search for hidden threats within your network. Use advanced analytics and threat intelligence feeds (covered earlier) to detect indicators of compromise (IoCs) and potential attack patterns before they escalate into full-blown incidents.

For those familiar with Microsoft Defender XDR, this powerful platform can be set up and configured in under an hour. One of its best features is the Advanced Hunting capability. Using the Kusto Query Language (KQL), you can create custom detection rules to discover anomalous and potentially malicious activity within your environment.

My friend Harri has done a lot of great work in this area. He’s published a very neat collection of advanced hunting and incident response queries on his Github here.

By focusing on these three key areas—knowing your data, network, and adversary—you can build a comprehensive, proactive threat defence strategy that significantly enhances your and your organisation's security posture and, in the absolute worst case, gives you more time to detect and respond appropriately.

Remember that proactive defence is an ongoing process that requires continuous improvement and adaptation to stay ahead of evolving threats.

Lastly, I’ll leave you with these wise words from Charles Darwin on the power of adaptation to change.

Thanks a lot for reading!

If you liked this article and want to stay up-to-date with more practical and value-driven insights in Cyber, hit that subscribe button below! :)

Previous
Previous

Calculating The Environment Protection Score (EPS)

Next
Next

Zero Trust Architecture: ISO vs. MITRE ATTACK